Earlier quoted context omitted.
> That's not end-to-end encryption. What do I have wrong here? Apparently, email may not their main e2ee usecase. The CEO at Skiff wrote this on PrivacyGuides forums: Our solution for external sharing was not intended for email. It is much more powerful to share E2EE real-time collaborative docs/files with subpages, embedded E2EE files, and so much more. Curiously, in the same thread, there's is a mention of Trail of…
See https://skiff.com/transparency , Trail of Bits has performed 2 audits, Cure53 1 audit, and we had an additional audit 2.5 years ago.
Your transparency statement clearly says that Security audits. This is different than privacy audits. You cannot audit privacy, since you can intentionally change the functionality of your software right after the audit.
For the same reason, you cannot share open-source version of your software and say that it respects privacy. That can be only said if you use reproducible builds, and for client software only.
Both security audits and sharing your software as open, is about security, not the privacy. Open-source software and security audits help to reduce unintentional issues. And in this context it means a lot.